Описание
A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to version 1.11.0 which addresses this issue.
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.11.0 (исключая)
cpe:2.3:a:apache:avro:*:*:*:*:*:.net:*:*
EPSS
Процентиль: 69%
0.00591
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-770
CWE-770
Связанные уязвимости
CVSS3: 7.5
redhat
около 4 лет назад
A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to version 1.11.0 which addresses this issue.
CVSS3: 7.5
github
около 4 лет назад
Allocation of Resources Without Limits or Throttling in Apache Avro
EPSS
Процентиль: 69%
0.00591
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-770
CWE-770